Page 1 of 1

Secure boot certificates expiration

Posted: 11 Dec 2025, 18:00
by Duke

Secure boot certificates expiration

Posted: 11 Dec 2025, 20:23
by teknixstuff
The expiration of these certificates will not invalidate existing files signed by them. It will just prevent new files being signed by them (so new Windows versions will not run). Also, all spec-compliant systems will have some method of adding a custom certificate (either via the firmware config, via Microsoft's certificate update, or via Shim and Machine Owner Key). Plus, most systems allow you to disable Secure Boot, which fixes this whole situation.

Secure boot certificates expiration

Posted: 11 Dec 2025, 21:33
by The-10-Pen
I have a hunch that Secure Boot and TPM technologies will not be able to be disabled in the near future.
My newest laptop (now 1.5yrs old) wouldn't even allow Win *TEN* to be installed *IF* the TPM drivers were contained within the installation media.
It's a Ryzen 5 with a copilot button on the keyboard.
I never bothered to even test copilot and the default Win11 that came with the laptop.
All new equipment gets an immediate reformat/reinstall before it even gets connected to the network.